Suricata Ruleset Management Web Application
ID: 620127e8-3145-5e2b-bf61-bb4a9e18f062
STIX ID: report--620127e8-3145-5e2b-bf61-bb4a9e18f062
Feed Name: Darknet
DumpBrowserSecrets is a publicly released post‑exploitation credential‑harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, history and bookmarks from major Chromium‑based browsers and Firefox on Windows. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface, handles DPAPI and NSS encryption models for other browsers, and includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, file‑handle duplication and a custom SQLite parser). The tool outputs structured JSON for red team usage, poses a high operational risk for account takeover and lateral movement if used by an adversary, and the report highlights detection and mitigation opportunities such as monitoring IElevator calls, suspicious headless browser instantiation, and non‑browser reads of browser SQLite stores.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
